Fleuret AI raises €4M pre-seed to automate penetration testing
Fleuret AI raised a €4M pre-seed led by RAISE Ventures, with Stoïk, GitGuardian, Vade and Almond founders aboard, to sell continuous AI pentests at a fraction of the audit price.
Also see more funding coverage: /funding/
Founded 2026 · Paris, France
Paris-based Fleuret AI has raised a €4M pre-seed round led by RAISE Ventures to automate penetration testing with AI agents, joined by Auriga Cyber Ventures, Wind Capital, Better Angle and a bench of French cybersecurity founders.
The annual pentest is one of security’s oldest rituals: expensive, slow, and out of date the week the report lands. The encouraging part is that the challengers are no longer waiting for the big consultancies to fix it – this one is a team of about ten people in Paris, selling the audit as a subscription.
Four cyber founders on one pre-seed cap table
Announced on 5 October 2026, the round was led by RAISE Ventures, the venture arm of the Paris investment group RAISE, with Auriga Cyber Ventures, Wind Capital and Better Angle participating.
The angel line is the tell. Jules Veyrat and Alexandre Andreini of cyber insurer Stoïk, GitGuardian chief executive Eric Fourrier, Vade co-founder Georges Lotigier and Almond co-founders Olivier Pantaleo and Jean-François Aliotti all joined, per the company’s announcement. That is four French cybersecurity companies’ worth of founders on a single pre-seed.
The money goes to hiring – AI specialists, software engineers and offensive security experts – and to accelerating the platform. “We don’t just want to automate pentesting as it exists today,” said co-founder and CEO Yanis Grigy in the announcement. “Our ambition is to build the offensive cybersecurity layer that will allow companies, whatever their size, to stay secure all year round.”
Two agents named Emile and Champollion
Fleuret AI was founded in 2026 by Yanis Grigy and CTO Augustin Ponsin. The product runs penetration tests on web applications and APIs with two AI agents, Emile and Champollion, which map a company’s environment, probe for vulnerabilities, demonstrate that each finding is actually exploitable with reproducible proof-of-concept evidence, and re-test once the fix ships, per the announcement and the company’s own site.
The operational details are aimed squarely at European buyers: findings flow into Jira, Linear and Slack, reports map to NIS2, DORA and ISO 27001, and the agents run from European infrastructure rather than a US cloud (fleuret.ai, October 2026). Early customers include Brevo, Stoïk and Yogosha. The company prices a pentest at €4,000, against the €15,000-30,000 it says traditional firms charge (fleuret.ai, October 2026).
And yes, the name is a fencing reference – a fleuret is the foil you train with before anyone hands you a sabre. For a product that attacks you politely and writes up the wounds, we have seen far worse branding.
A $1.98bn market compounding at 14.2%
The segment is measurable, for once. The global penetration testing market stands at $1.98bn in 2025 and is projected to reach $4.39bn by 2031, a 14.2% CAGR (MarketsandMarkets, March 2026). The growth is not mysterious: NIS2 and DORA have turned the periodic security test from best practice into a regulatory obligation across the EU, and testing capacity has not kept up with the paperwork.
Our own records put the cheque in context. In the past fortnight alone we covered Kontext’s $4M seed led by 42CAP to police what AI agents do inside company systems, and Osavul’s €8.5M Series A led by 33N Ventures for hybrid threat intelligence. European cybersecurity is producing a funded round a week right now, and the cheques cluster at exactly this early stage – the running tally is in our fundraising data.
When the operators write the cheques
So what does a €4M pre-seed for a ten-person team tell us? First, that AI agents are repricing services markets, and investors are paying seed-sized premiums for the teams doing the repricing. A test that cost €20,000 and three weeks now has a challenger at €4,000 and a few hours; the delta is the business model.
Second – and this is the quietly European part – the cap table is the French cyber ecosystem giving back. Founders from Stoïk, GitGuardian, Vade and Almond backing the next offensive security company is the operator-angel flywheel we usually admire from afar in the US, running at home. The good news is that every ingredient here is local: the capital, the angels, the infrastructure and the regulation the product answers to all come from the same ecosystem it sells into.
Third, sovereignty is now a sales feature, not a slide. Running offensive agents from European infrastructure, for buyers answering to NIS2 and DORA, is a specific advantage a European founder can price – what we are seeing is compliance pressure converting directly into pipeline for local vendors.
Keep an eye on the continuous-security line: when the audit becomes a subscription, the rest of the compliance stack tends to follow. En garde.